TruffleHog – Searches through Git repositories for high entropy strings
github.com
github.com
EDIT: I see now. http://blogs.splunk.com/2015/10/01/random-words-on-entropy-a...
So you're looking for hashes gotcha.
An alternative that worked surprisingly well (though, not without flaws) was to use a password strength checker similar to python's passwordmeter library.
Note that bandit is for python, so it'll only match against potential secrets hardcoded into python code, but it takes the AST in mind, so the signal is way higher.